First published: Fri Apr 08 2022(Updated: )
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=5.17<5.17.1 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Fedoraproject Fedora | =35 | |
Netapp Active Iq Unified Manager Vsphere | ||
Netapp Solidfire\, Enterprise Sds \& Hci Storage Node | ||
Netapp Solidfire \& Hci Management Node | ||
Netapp Hci Compute Node Firmware | ||
Netapp Hci Compute Node | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H300e Firmware | ||
Netapp H300e | ||
Netapp H500e Firmware | ||
Netapp H500e | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Netapp H410c Firmware | ||
Netapp H410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28796 is a vulnerability in the Linux kernel before version 5.17.1 that allows a use-after-free caused by a transaction_t race condition in the jbd2_journal_wait_updates function in fs/jbd2/transaction.c.
CVE-2022-28796 is considered high severity with a CVSS score of 7.
The Linux kernel versions before 5.17.1, Redhat Enterprise Linux versions 6.0 and 7.0, and Fedoraproject Fedora version 35 are affected by CVE-2022-28796.
To fix CVE-2022-28796, it is recommended to update to the Linux kernel version 5.17.1 or later.
You can find more information about CVE-2022-28796 in the following references: [Link 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1), [Link 2](https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e), [Link 3](https://security.netapp.com/advisory/ntap-20220506-0006/).